package com.ymy.login;
import java.sql.*;
import java.util.*;
public class JDBCTest {
public static void main(String[] args) {
//1、初始化一个界面
Map<String,String> userLoginInfo = initUI();
//2、验证用户名密码
boolean loginResult = login(userLoginInfo);
//3、输入结果
System.out.println(loginResult ? "登陆成功!":"登陆失败!");
}
/**
* 用户登陆
* @param userLoginInfo
* @return false表示登陆失败,true表示登陆成功
*/
private static boolean login(Map<String, String> userLoginInfo) {
//标识符初始值为false
boolean flag = false;
//编写JDBC代码
ResourceBundle bundle = ResourceBundle.getBundle("MyJDBC");
String driver = bundle.getString("driver");
String url = bundle.getString("url");
String user = bundle.getString("user");
String password = bundle.getString("password");
Connection conn = null;
PreparedStatement ps = null;
ResultSet rs = null;
String sql = "select * from t_user where username = ? and password = ?";
try{
//1、加载MySQL驱动
Class.forName(driver);
//2、创建连接
conn = DriverManager.getConnection(url, user, password);
//3、创建sql操作对象 进行预编译并且给占位符(问号传值)
ps = conn.prepareStatement(sql);
ps.setString(1, userLoginInfo.get("loginUserName"));
ps.setString(2, userLoginInfo.get("loginPassWord"));
//4、执行sql
rs = ps.executeQuery();
//5、处理结果集
if(rs.next()) {
flag = true;
}
}catch(Exception e) {
e.printStackTrace();
}finally {
if(rs!=null) {
try {
rs.close();
} catch (SQLException e) {
// TODO Auto-generated catch block
e.printStackTrace();
}
}
if(ps!=null) {
try {
ps.close();
} catch (SQLException e) {
// TODO Auto-generated catch block
e.printStackTrace();
}
}
if(conn!=null) {
try {
conn.close();
} catch (SQLException e) {
// TODO Auto-generated catch block
e.printStackTrace();
}
}
}
return flag;
}
/**
* 初始化用户界面
* @return 用户输入的用户名和密码等登陆信息
*/
private static Map<String, String> initUI() {
Scanner in = new Scanner(System.in);
System.out.println("用户名:");
String loginUserName = in.nextLine();
System.out.println("密码");
String loginPassWord = in.nextLine();
Map<String,String> userLoginInfo = new HashMap<>();
userLoginInfo.put("loginUserName", loginUserName);
userLoginInfo.put("loginPassWord", loginPassWord);
return userLoginInfo;
}
}
解决了SQL注入问题的JDBC代码
最新推荐文章于 2022-10-09 07:15:00 发布